Hi all,
Ive upgraded one of our FWs from r80.10 -> r80.40, and now I am recieving the below error for endpoint VPN connections.
"You are not authorized to recieve and office mode IP address"
The only untoward message I can find in vpn.elg debug is below - but possibly a red herring, not certain.
[vpnd 5997 4126250688]@CPFW-R77.20[10 June 13:40:22] check_uint_attribute_value: failed to get attribute [sr_info_auth_grps_fetched] from userobject
[vpnd 5997 4126250688]@CPFW-R77.20[10 June 13:40:22] check_uint_attribute_value: read attribute [sr_info_auth_grps_fetched] on user object, value is 0
The above error is mentioned in SK115352 >> however, user has NOT got multiple accounts internal and ldap, so I dont believe its a valid fix here.
SmartLog shows the authentication as successfull, but without any further entries.
The other GW is still on r80.10, and working fine with the same policy. Im not sure if that may have some impact here with differing versions.
Also, the clients use a certificate to authenticate. Im wondering has something changed with .10 and .40 in terms of certificates. The certificate is self signed.
Any thoughts much appreciated.
D